Privacy Policy
Effective [EFFECTIVE DATE]
Cohara is bookkeeping software for small-business owners, operated by [LEGAL ENTITY NAME]. This policy describes what the product collects, what it deliberately does not, and every outside company that receives any of it.
What we collect
Your account. An email address and a password, held by our authentication provider. We never see the password.
Your business profile. The business name, industry, primary state, and optionally a tax entity type and fiscal year — the details reports and export templates need.
Documents you upload. Bank and card statements, receipts, invoices, check images, and spreadsheet or bank-download files. We store the file itself and the text read out of it.
Transactions. Dates, amounts, descriptions, the category you assign, and any note you add — whether they came from a document you uploaded or a bank you connected.
Connected accounts. The institution name, the account name and type, and the last four digits. See Bank connections below for what we hold to keep the connection working.
People you record. If you use the invoicing, vendor, or workforce features, you enter details about other people — customers, contractors, employees. That information is yours; we hold it so the product can show it back to you, and we do not use it for anything else.
What we never collect
These are enforced in the software, not just intended. Each is checked by an automated test that fails the build if it stops being true.
- Your bank login.There is no field for a bank username or password anywhere in Cohara. When you connect a bank, you sign in inside the provider’s own window and we never see what you type.
- Full account, routing, or card numbers. The database physically cannot store more than four digits — the columns reject anything longer.
- Your money. Cohara cannot move funds. Bank connections are read-only, and there is no transfer or payment-initiation feature in the product.
Bank connections
If you connect a bank, we use Plaid (and in some deployments, Teller) to do it. You sign in with your bank inside their window, and they return an access token that lets us read transactions. That token is encrypted before it is stored, kept in a table your browser session has no permission to read, and used only to fetch transactions and balances.
The connection is read-only. When you disconnect a bank, we tell the provider to revoke the connection at their end as well as deleting our copy — a disconnection that only tidied our own records would leave your bank authorised to share data with a company you had stopped using.
Transactions already in your books stay there when you disconnect, because they are your bookkeeping records.
Who else receives data
We do not sell personal information, and we do not share it for advertising. These companies process data because the product cannot work without them:
- Supabase — the database, file storage, and sign-in system. Everything described above lives here.
- Vercel — hosting. Serves the application and keeps operational logs.
- Plaid, and in some deployments Teller — bank connections, if you choose to connect one.
- Stripe — subscription billing, and card payments on invoices if you enable them. Card details go to Stripe directly and never through Cohara.
- Square, Clover, and Helcim — sales and payment data, only for the ones you connect.
- Resend — sending invoices and reminders by email, if you use those features.
- Bandwidth — sending and receiving text messages, if you switch texting on. The phone number and the text of the message go to Bandwidth, because that is what sending a text is. Bandwidth also tells us whether a message arrived, and passes on replies — including someone replying STOP, which we record as them opting out.
We may also disclose information if the law requires it, or to protect the rights and safety of people using the product.
Automated reading of documents
Reading a statement happens on our own servers. On deployments where the operator has enabled the optional model-assisted reader, the textof an uploaded statement may also be sent to OpenAI to help identify transactions. The file itself is never sent, the text is not used to train anyone’s model, and the feature is off unless explicitly switched on.
A machine reading is never the last word. Anything uncertain is put in front of you to confirm, and nothing reaches your books without you filing it.
Keeping and deleting
We keep your data for as long as your account exists, because bookkeeping records are useful to you for years — tax authorities generally expect them to be retained well after the year they belong to.
You can, at any time:
- Disconnect a bank, which revokes our access at the provider
- Delete individual documents and transactions
- Export your records, so leaving does not mean losing them
- Ask us to delete your account and everything in it, by writing to [PRIVACY CONTACT EMAIL]
Some records may persist briefly in encrypted backups after deletion, and we may keep what the law requires us to keep.
Security
Every table is protected by row-level security, so one owner’s data cannot be returned to another owner’s session even if a query is written wrongly. Bank and point-of-sale tokens are encrypted before storage and are held where no browser session can read them. Traffic is encrypted in transit.
No system is perfectly secure, and we will not pretend otherwise. If a breach affects your information we will tell you.
Your rights
Depending on where you live, you may have the right to see the personal information we hold about you, correct it, delete it, or receive a copy in a portable form. Write to [PRIVACY CONTACT EMAIL] and we will respond.
We do not sell or share personal information as those terms are used in California law, and we do not use it for targeted advertising.
Children
Cohara is for business use and is not directed to anyone under 18. We do not knowingly collect information from children.
Changes
If this policy changes we will update the date at the top, and we will tell you directly if the change is material.
Contact
[LEGAL ENTITY NAME] — [PRIVACY CONTACT EMAIL]
Cohara organizes your records. It is not a tax, legal, or accounting service, and nothing in the product is advice.